Courseiva
mediumMultiple ChoiceObjective-mapped

MS-102 Practice Question: A company uses Azure AD Privileged Identity…

A company uses Azure AD Privileged Identity Management (PIM) to manage role activations. They have an Azure AD Premium P2 license. The security team wants to require that any activation of the Exchange Administrator role must be approved by a specific group named 'Exchange Approvers'. Additionally, activations must require a ticket number and expire after 6 hours. Which PIM configuration should the administrator modify?

⚠ Common exam trap

Candidates often confuse 'eligible assignments' (who can activate a role) with 'approvers' (who must approve activations), leading candidates to incorrectly select Option B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure the 'Role settings' for the Exchange Administrator role to require approval and set the approvers group

In Azure AD PIM, the 'Role settings' for a specific role (like Exchange Administrator) allow you to configure activation requirements, including requiring approval, specifying approvers (such as the 'Exchange Approvers' group), requiring a ticket number, and setting a maximum activation duration (e.g., 6 hours). This directly meets all the security team's requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure the 'Role settings' for the Exchange Administrator role to require approval and set the approvers group

    Why this is correct

    In Azure AD PIM, role settings for the Exchange Administrator role live under 'Role settings' in PIM. Editing this configuration lets you toggle 'Require approval to activate' and specify one or more approver groups or users; you can also enforce justification and ticket-number fields. Setting the Exchange Approvers group as the approver group ensures that every activation request is first reviewed by the designated approvers before the role becomes active. This is the only option that actually enforces an approval gate at activation time.

  • Add the Exchange Administrator role to the 'Exchange Approvers' group's eligible assignments

    Why it's wrong here

    Adding the Exchange Administrator role to the 'Exchange Approvers' group's eligible assignments would make members of that group eligible to activate the Exchange Administrator role themselves, not to act as approvers for other users' activations. Approvers are selected in the role's 'Role settings' page, not through eligible assignments. In fact, this action would broaden access by giving the Exchange Approvers group the ability to self-request the privileged role, which is the opposite of what the company wants.

  • Create a PIM alert for activations without a ticket number and set a 6-hour alert threshold

    Why it's wrong here

    PIM alerts are reactive detection mechanisms that generate notifications for suspicious activities—like repeated role activations or roles assigned outside PIM—but they do not enforce activation requirements. Configuring an alert for activations without a ticket number would only flag such events after the fact; it would not require approval or block the activation. A 6-hour threshold is an alert scheduling/tuning parameter, not an activation policy, so it has no bearing on whether approval is required.

  • Define an access review for the Exchange Administrator role with a 6-hour review duration

    Why it's wrong here

    Azure AD access reviews are designed for periodic attestation of who still needs access—reviewers can approve or remove existing eligible/active assignments on a schedule, such as weekly or quarterly. Defining a review for the Exchange Administrator role would not affect the activation process itself; it would only check the continued validity of assignments after they have been granted. A six-hour review duration is also inconsistent with how access reviews work, because they are not timed per activation but run as recurring self-contained reviews, making this ineffective for enforcing approvals.

About these practice questions

One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.